Restricting AKS API server access to specific networks is done with authorized IP address ranges
You have an Azure subscription that contains an Azure Kubernetes Service (AKS) cluster named AKS1. You have an Azure container registry that stores container images that were deployed by using Azure DevOps Microsoft-hosted agents. You need to ensure that administrators can access AKS1 only from specific networks. The solution must minimize administrative effort. What should you configure for AKS1?
Community Votes
57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Authorized IP ranges are the lightweight, built-in control for 'access only from specific networks'. A private cluster or private endpoint changes the network topology and costs more to operate; the question's 'minimize administrative effort' points to authorized IP ranges.
To let administrators reach the AKS API server only from specific networks, you configure authorized IP address ranges on the cluster. This lets you allowlist the IP ranges (such as your admin jump-host or corporate CIDR) that can reach the Kubernetes API server, with minimal operational overhead.
Candidates pick a private cluster or private endpoint, but those isolate the API server on a private network rather than allowlisting specific admin networks; the direct 'only from specific networks' control is authorized IP address ranges.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Authorized IP address ranges let you specify the CIDR ranges permitted to access the AKS API server. When you need administrators to reach AKS1 only from certain networks and want to minimize effort, enabling authorized IP ranges is the targeted, built-in solution. (Option A)Why the Other Options Are Wrong
- Option B (Application Gateway Ingress Controller) manages ingress traffic to workloads, not administrative access to the API server.
- Option C (Private endpoint) is a connectivity mechanism; it does not by itself restrict access to specific admin networks and adds setup overhead.
- Option D (Private cluster) places the API server on a private network, which is heavier to operate than simply allowlisting IP ranges and is not the minimal-effort answer the question seeks.